peter bassill · operator
$ cve CVE-2009-0689 JSON

CVE-2009-0689 EXPLOIT

6.8
MEDIUM · CVSS 2.0 · EPSS 28.1% (pctl 98)

Patch early

A public exploit exists.

Description

Array index error in the (1) dtoa implementation in dtoa.c (aka pdtoa.c) and the (2) gdtoa (aka new dtoa) implementation in gdtoa/misc.c in libc, as used in multiple operating systems and products including in FreeBSD 6.4 and 7.2, NetBSD 5.0, OpenBSD 4.5, Mozilla Firefox 3.0.x before 3.0.15 and 3.5.x before 3.5.4, K-Meleon 1.5.3, SeaMonkey 1.1.8, and other products, allows context-dependent attackers to cause a denial of service (application crash) and possibly execute arbitrary code via a large precision value in the format argument to a printf function, which triggers incorrect memory allocation and a heap-based buffer overflow during conversion to a floating-point number.

Scoring

CVSS6.8 (MEDIUM, v2.0)
VectorAV:N/AC:M/Au:N/C:P/I:P/A:P
EPSS28.05% — more likely to be exploited than 98% of all CVEs
WeaknessCWE-119
On CISA KEVno
Public exploityes
Published2009-07-01
Last modified2026-06-16

Affected (6)

VendorProduct
freebsdfreebsd
k-meleon projectk-meleon
mozillafirefox
mozillaseamonkey
netbsdnetbsd
openbsdopenbsd

Public exploits

References

→ the Explorer  ·  watch your stack  ·  NVD